CWE-863
3,308 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVEs (3,308)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Quest 1Kace System Management Appliance Nov 21, 2024 May 31, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The 'systemui/settings_network.php' and 'systemui/settings_patching.php' scripts in the Quest KACE System Management Appliance 8.0.318 are accessible only from localhost. This restriction can be bypassed by modifying the...Show more |
OpenFlow version 1.0 onwards contains a Denial of Service and Improper authorization vulnerability in OpenFlow handshake: The DPID (DataPath IDentifier) in the features_reply message are inherently trusted by the control...Show more |
1Ibm 8San Volume Controller Firmware Spectrum VirtualizeSpectrum Virtualize For Public Cloud+5 moreNov 21, 2024 May 17, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticate...Show more |
1Ibm 8San Volume Controller Firmware Spectrum VirtualizeSpectrum Virtualize For Public Cloud+5 moreNov 21, 2024 May 17, 2018 N/A· v4 7.6 HIGH· v3 6.5 MEDIUM· v2 IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtualize and IBM FlashSystem products ( 6.1, 6.2, 6.3, 6.4, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.6.1, 7.7, 7.7.1, 7.8, 7.8.1, 8.1, and 8.1.1) could allow an authenticate...Show more |
1Pivotal Software 1Pivotal Application Service Nov 21, 2024 May 11, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Apps Manager included in Pivotal Application Service, versions 1.12.x prior to 1.12.22, 2.0.x prior to 2.0.13, and 2.1.x prior to 2.1.4 contains an authorization enforcement vulnerability. A member of any org is able to...Show more |
5Netapp OraclePivotal Software+2 more42Agile Plm Application Testing SuiteBig Data Discovery+39 moreNov 21, 2024 May 11, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to met...Show more |
2Jenkins Redhat2Jenkins OpenshiftNov 21, 2024 May 8, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing...Show more |
1Cisco 1Secure Firewall Management Center Nov 26, 2024 May 2, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the management console of Cisco Firepower System Software could allow an unauthenticated, remote attacker to access sensitive data about the system. The vulnerability is due to improper cross-origin do...Show more |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreJun 17, 2026 May 2, 2018 N/A· v4 4.4 MEDIUM· v3 3.5 LOW· v2 On an F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.1, or 11.2.1-11.6.3.1 system configured in Appliance mode, the TMOS Shell (tmsh) may allow an administrative user to use the dig utility to gain unauthorized access to file...Show more |
1Vaultize 1Enterprise File Sharing May 30, 2025 Apr 25, 2018 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 An issue was discovered in Vaultize Enterprise File Sharing 17.05.31. There is improper authorization leading to creation of folders within another account via a modified device value. |
1Ibm 7Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 moreNov 21, 2024 Apr 24, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (R...Show more |
1Cisco 1Digital Network Architecture Center Nov 21, 2024 Apr 19, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the web framework of the Cisco Digital Network Architecture Center (DNA Center) could allow an unauthenticated, remote attacker to communicate with the Kong API server without restriction. The vulnerab...Show more |
1Schneider Electric 166074 Mge Network Management Card Transverse Jun 17, 2026 Apr 18, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices co...Show more |
1Redhat 4Jboss Enterprise Application Platform Jboss FuseUndertow+1 moreNov 21, 2024 Apr 18, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP r...Show more |
Jenkins before versions 2.44 and 2.32.2 is vulnerable to an insufficient permission check. This allows users with permissions to create new items (e.g. jobs) to overwrite existing items they don't have access to (SECURIT...Show more |
An improper authorization vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTemplate.java, ConvertToVm.java, Delete.java, DeleteSnapshot.java, Deploy.java,...Show more |
1Ibm 1Business Process Manager Nov 21, 2024 Mar 30, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is not assigned to. IBM X-Force ID: 136151. |
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see eve...Show more |
Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users. |
2Debian Gitlab2Debian Linux GitlabNov 21, 2024 Mar 21, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user login. |